RLSA-2023:0095
Moderate: libtiff security update
Topic
An update is available for libtiff.
This update affects Rocky Linux 8.
A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list
Description
The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files.
Security Fix(es):
* LibTiff: DoS from Divide By Zero Error (CVE-2022-2056, CVE-2022-2057, CVE-2022-2058)
* libtiff: Double free or corruption in rotateImage() function at tiffcrop.c (CVE-2022-2519)
* libtiff: uint32_t underflow leads to out of bounds read and write in tiffcrop.c (CVE-2022-2867)
* libtiff: tiffcrop.c has uint32_t underflow which leads to out of bounds read and write in extractContigSamples8bits() (CVE-2022-2869)
* libtiff: tiffcrop: heap-buffer-overflow in extractImageSection in tiffcrop.c (CVE-2022-2953)
* libtiff: Assertion fail in rotateImage() function at tiffcrop.c (CVE-2022-2520)
* libtiff: Invalid pointer free operation in TIFFClose() at tif_close.c (CVE-2022-2521)
* libtiff: Invalid crop_width and/or crop_length could cause an out-of-bounds read in reverseSamples16bits() (CVE-2022-2868)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Rocky Linux 8
SRPMs
- libtiff-0:4.0.9-26.el8_7.src.rpm
RPMs
- libtiff-0:4.0.9-26.el8_7.i686.rpm
- libtiff-0:4.0.9-26.el8_7.x86_64.rpm
- libtiff-0:4.0.9-26.el8_7.aarch64.rpm
- libtiff-debuginfo-0:4.0.9-26.el8_7.aarch64.rpm
- libtiff-debuginfo-0:4.0.9-26.el8_7.i686.rpm
- libtiff-debuginfo-0:4.0.9-26.el8_7.x86_64.rpm
- libtiff-debugsource-0:4.0.9-26.el8_7.aarch64.rpm
- libtiff-debugsource-0:4.0.9-26.el8_7.i686.rpm
- libtiff-debugsource-0:4.0.9-26.el8_7.x86_64.rpm
- libtiff-devel-0:4.0.9-26.el8_7.aarch64.rpm
- libtiff-devel-0:4.0.9-26.el8_7.i686.rpm
- libtiff-devel-0:4.0.9-26.el8_7.x86_64.rpm
- libtiff-tools-0:4.0.9-26.el8_7.aarch64.rpm
- libtiff-tools-0:4.0.9-26.el8_7.x86_64.rpm
- libtiff-tools-debuginfo-0:4.0.9-26.el8_7.aarch64.rpm
- libtiff-tools-debuginfo-0:4.0.9-26.el8_7.x86_64.rpm
Issued: 1/12/2023
Type: Security
Severity: Moderate
Affected Product
- Rocky Linux 8
Fixes
CVEs
References
- No references